Privacy policy — Table Companion
1. Who is responsible
Table Companion is published by Julien Juret, based in Canada. For privacy questions, access or deletion requests, contact julien.juret@gmail.com. The app serves English- and French-speaking users, including users in the European Union. Table Companion is not intended for children under 13.
2. Local play and the connection service
Campaigns, character sheets, handouts, portraits, chat and dice history are stored on participating devices and shared with the players selected by the game master. Local play can work without internet. Remote play uses encrypted peer connections, with a relay when needed. Other participants can retain material they receive; removing it on your device cannot recall their copies.
Online features use a persistent, pseudonymous device identifier, not a named account. The service stores that identifier, a hash of its authentication token, platform and creation/last-activity dates. It also processes connection IP addresses, invitation codes, table identifiers, connection metadata and optional Foundry world references. A technical identifier is not anonymous merely because no email address is required.
3. Optional Foundry connection
When you link Foundry, the app sends the server address, username and password to our connector. The service encrypts credentials at rest with a server-held key; it can decrypt them to connect on your behalf. It stores world metadata, raw document projections needed for synchronization (including actors, items, scenes, users, combat, chat, journals and folders) and queued writes. This information is readable by the connector; it is not end-to-end encrypted from the operator.
An encrypted recovery bundle can remain on your device. Your device cannot decrypt it, but our service can. Linking a world can send information about other players to this service. Tell them about this policy and only connect a world you are authorized to share. Their information comes from that Foundry world. Deleting a linked world removes its credentials, projections, membership and queued writes from the active service; backup expiry is separate.
4. Optional campaign backups and exported files
If you enable an encrypted campaign copy, the app encrypts it on your device before uploading. The content key is derived from your recovery code and is not sent to the service. We store the encrypted file and metadata: owner device ID, recovery-token hash, size and creation/activity dates. Our service cannot read the campaign contents from that copy.
You can restore the encrypted copy using its recovery code. Keep that code private. Deletion of the online copy also requires the uploading device identity; if you have lost that device, contact us for help. An ordinary exported .tcbackup file is not this encrypted relay copy: it can contain the whole campaign and hosting credentials. Share and store it carefully. Device-level backups or transfers are also subject to your operating-system settings.
5. On-device AI, scanning and Google services
On supported Apple devices, NPC descriptions can be written on-device by Apple Foundation Models. Prompts use limited NPC context, such as a preferred name, language and flavor tags; nothing is sent to us or to a hosted language-model service. When a game master first generates an NPC in a session, the app may ask iOS for the user’s age range; the answer stays on the device and is not stored, and if iOS reports a user under 18 the app uses its bundled descriptions instead. Bundled descriptions are also used when the device model is unavailable, and always on Android.
Android uses Google code scanning. Although ML Kit processes input and output on-device, Google may receive SDK metrics, including device/app information, identifiers, API usage, performance, configuration and errors, and may deliver models or updates. See ML Kit privacy terms, data disclosures and Google’s privacy policy. Table Companion does not run advertising or sell personal data. On-device processing does not mean that the SDK sends no diagnostics.
6. Purposes and legal bases
Where the GDPR applies, we process the information necessary to provide the online functions you request on the basis of performing our agreement with you (Article 6(1)(b)). We use limited security and operational records to protect the service, prevent abuse and investigate faults on the basis of legitimate interests (Article 6(1)(f)); our interest is keeping private game sessions and the service secure. We process rights requests and records required by law to meet legal obligations (Article 6(1)(c)).
Feature permissions and acceptance of usage rules are not blanket consent to data processing. If a processing operation requires consent under applicable law, that consent must be obtained separately and can be withdrawn. Declining an optional feature prevents its associated feature processing. Essential connection data is needed to provide online connections. We do not use personal data for advertising profiles or decisions producing legal or similarly significant effects.
7. Recipients and international processing
Information is disclosed as needed to participating players, a Foundry server you choose, infrastructure providers operating our connection and storage services, and Google for its Android SDK services. Our hosting provider is OVHcloud. Authorized operator access is limited to operating, securing and supporting the service; we may disclose information when legally required.
The publisher is in Canada. Your chosen peers and Foundry server may be in other countries, and Google operates internationally under its published terms. Contact us for information about the infrastructure locations, recipients and transfer arrangements relevant to your use. Encryption does not by itself replace the safeguards required for an international transfer.
8. Retention and deletion
Invitations expire after 24 hours without renewal. Temporary queued connection offers/candidates expire within 60 seconds; TURN credentials expire after one hour. Unused campaign relay copies expire after 90 days without a fetch or upload. Device identities are eligible for deletion after 180 days without activity only when they no longer own or belong to a world and hold no backup. Linked-world records remain until the link is deleted. Completed write-queue records and projection tombstones have 30-day retention rules.
Request logs include method, path, status, size, duration, request ID and device ID. They are used for operation and security, not advertising. Versioned container configuration rotates logs by size (five 50 MB files per configured container), so elapsed retention varies with traffic. The backup configuration retains local database recovery snapshots for approximately seven days and expires matching off-box snapshots after eight complete days on a successful backup run. Its deployment and the provider’s separate object-version retention must be verified; contact us for the actual retention applicable to your request. Deletion from active storage does not immediately erase a recovery snapshot or a copy held by another participant. Contact us to request deletion of server-held information and to understand any justified retention; uninstalling the app alone is not a server deletion request.
9. Permissions and your choices
The app asks for permissions needed by the features you use, including local network discovery, notifications and optional device media functions. Android’s code scanner uses Google Play Services and does not require this app to hold camera permission. You can review permissions in system settings. Online backups and Foundry links are optional; local play does not require either.
10. Your rights, safety and changes
Depending on applicable law, you may request access, correction, deletion, restriction, portability or object to processing, including processing based on legitimate interests. Where consent is the basis, you can withdraw it without affecting earlier lawful processing. Contact the address above; do not send passwords, device tokens, backup codes or whole campaigns. We may ask for proportionate information to verify your request, and will respond within the applicable legal deadline.
EU users may complain to their local data-protection supervisory authority. Canadian users may contact the relevant federal or provincial privacy regulator. We can help direct an inquiry. To report unsafe or unlawful content, use the same contact, describe the issue and share only material you are authorized to disclose. If you believe a child under 13 has provided information, contact us. Changes to this policy are dated above; material changes will also be brought to users’ attention where required.